SCA: security update for org.http4s:http4s-ember-server_2.12, org.http4s:http4s-ember-server_2.13, org.http4s:http4s-ember-server_3 (GHSA-fm4g-76c9-7w69)

high Tenable Self-Hosted Container Security Plugin ID 448001

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server
middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce
comparison is inverted. On an application that protects at least one route with DigestAuth, an
unauthenticated attacker can repeatedly trigger authentication challenges, causing the persistent nonce
map to grow until the JVM exhausts heap memory. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
(CVE-2026-69208)

Solution

Update the org.http4s:http4s-ember-server_2.12 library and its related packages to version 0.23.35 or later.

See Also

https://github.com/advisories/GHSA-fm4g-76c9-7w69

Plugin Details

Severity: High

ID: 448001

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/16/2026

Updated: 9/16/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-69208

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2026

Vulnerability Publication Date: 9/15/2026

Reference Information

CVE: CVE-2026-69208